[HN Gopher] TLS Certificate Transparency logs don't always talk ...
___________________________________________________________________
TLS Certificate Transparency logs don't always talk to you
Author : rdpintqogeogsaa
Score : 8 points
Date : 2022-06-08 18:40 UTC (4 hours ago)
(HTM) web link (utcc.utoronto.ca)
(TXT) w3m dump (utcc.utoronto.ca)
| throwaway787544 wrote:
| Logs are there because any person at any CA can generate a cert
| for your domain and we want to know when that happens. We should
| fix that.
|
| A new standard could dictate that registrars and CAs have to work
| together. Specifically, customer uploads a public key to a
| registrar, and a CA has to use registrar's public key to validate
| a CSR. This makes it impossible to create a valid certificate
| without the domain owner's key - and not whoever took over the
| domain record for the moment that the CA validated. The browser
| should validate that the cert was signed using the key from the
| registrar.
|
| In this way even a rogue CA cert can't work on a client. Only a
| cert created by the domain owner will be valid. So only one CA
| and one key can create a valid cert.
| rektide wrote:
| With specs like WebBundle, sites could self-sign the log content,
| in a way where other people could securely mirror/cache another
| sites log resources in a way that's still clear & secure.
___________________________________________________________________
(page generated 2022-06-08 23:02 UTC)